Data Security Checklist for Leaving a Job

Leaving a job involves more digital cleanup than people expect β€” both protecting your own information and respecting what belongs to the company.

  1. Log out of and secure personal accounts

    Sign out of any personal email, cloud storage, or social media accounts you ever logged into on a work computer or shared device, and change those passwords for good measure.

  2. Separate personal information from work chat and email

    Clean up any personal conversations or files left in workplace messaging apps or your work email, and back up any personal information you linked to your work account beforehand.

  3. Transfer ownership of shared cloud documents

    For files or folders in a shared drive or workspace tool where you are listed as the owner, transfer ownership to a colleague or your manager before your last day so nothing gets orphaned.

  4. Don't take confidential company data with you

    Copying customer data, source code, or other internal materials to a personal device or personal email can carry real legal consequences under trade-secret and data-protection laws. Do not do it, even with good intentions.

  5. Only back up material you personally own

    Work you contributed to still generally belongs to the company, so if you want something for a portfolio, check your company policy and get your manager sign-off before taking a copy, rather than assuming it is fine.

  6. Review what your confidentiality agreement still requires

    Check whether the non-disclosure or confidentiality agreement you signed when you joined has obligations that continue after you leave, and ask HR if anything is unclear.

Protecting yourself is just as important as protecting the company

People tend to think of offboarding security as purely about protecting the company, but there is a personal side too. It is common to have logged a personal account into a work laptop at some point, or linked personal contacts and files to a work messaging app. Before you hand back your equipment, log everything out, remove saved passwords, and change your credentials β€” leaving personal accounts logged into a device that is about to be wiped and reissued is a real, avoidable privacy risk.

Why 'I helped make it' doesn't mean 'I can keep it'

It's natural to feel a sense of ownership over something you built, but in most employment relationships, work created as part of your job belongs to the employer, not to you personally, regardless of how much of the actual work was yours. If you want to keep a version of a project for your resume or portfolio, ask first rather than assuming it is fine to copy it on your way out. Many companies are willing to approve a sanitized version, with client names or proprietary details removed, if you ask before you leave.

Frequently Asked Questions

Can I keep a copy of a project I am proud of for my portfolio?

Ask your manager or HR before you leave rather than copying it on your own β€” many companies will approve a redacted or generalized version for portfolio use, but taking the original without permission can create real legal exposure even if your intentions are good.

What actually counts as confidential information under an NDA?

It typically covers things like client and customer data, internal financials, source code, product roadmaps, and other information not publicly available, but the exact scope depends entirely on the agreement wording. If you are unsure whether something specific is covered, ask HR or review the agreement itself rather than guessing.